Cernos

Privacy Policy

Effective August 25, 2026. This Privacy Policy explains how Cernos, operated by Complex Sales Intelligence LLC, handles information when you use app.cernos.app, Cernos for Outlook, Cernos for Gmail, Cernos Desktop, and the integrations you choose to connect (the “Service”).

Roles and Scope

This policy applies to people who visit, evaluate, or use the Service. Cernos is generally the controller of account, billing, security, and website information. When an organization uses Cernos to process its workspace content, contacts, CRM records, email, calendar, or meeting data, that organization normally controls the content and Cernos processes it to provide the Service. Its agreement with Cernos may provide additional terms.

Information We Handle

  • Account and identity. Name, email address, Clerk user ID, and provider identity claims.
  • Workspace content. Workspace details, prospects, customer contacts, CRM records, generated artifacts, and seller actions.
  • Integration credentials. OAuth access and refresh tokens, account labels, scopes, and sync status.
  • Billing. Plan, subscription status, Stripe customer and subscription IDs, billing email, and invoice-related information.
  • Operational and security data. IP address, request timing, device and browser information, audit events, and error logs.

We do not store your payment-card or bank-account number. Stripe processes payment details through its hosted checkout and customer portal. We do not store your password; browser authentication is provided by Clerk and connected-provider authentication uses OAuth.

Connected Services

Google Workspace. When you connect Google, Cernos requests gmail.readonly and calendar.readonly, as well as basic OpenID identity scopes. These permissions let Cernos read Gmail messages and Google Calendar events to provide the connected, user-facing account-context and meeting-preparation features. Cernos does not request Gmail send or modify access, calendar write access, Google Drive access, or Google Contacts access.

The use of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Cernos does not sell Google Workspace data, use it for advertising, or use it to train generalized AI or machine-learning models. You can revoke Cernos access through your Google Account permissions.

Microsoft 365 and Outlook. Two Microsoft surfaces request different permissions. The Outlook add-in signs the seller in through Nested App Authentication and requests delegated User.Read only, which identifies the signed-in seller. Connecting Microsoft 365 inside the Cernos web app is separate: it requests User.Read and Mail.Read, basic OpenID identity scopes, and offline_access so the connection can refresh without asking you to sign in again. Mail.Read permits Cernos to read the seller’s mailbox data needed for connected email context. Cernos does not request Mail.ReadWrite, Mail.Send, Files.Read, Contacts.Read, or calendar-write permissions.

When the Outlook pane is open, it may read the open message’s participants, subject, conversation identifiers, and a limited plain-text body excerpt to match the conversation and generate the pane. Cernos does not move, modify, send, or delete mailbox messages. Raw message bodies are used transiently for the requested feature and are not written as full message bodies to the Cernos workspace database.

CRM and meeting services. If you connect HubSpot, Salesforce, or Zoom, Cernos handles the records and meeting metadata that the connection is configured to make available, such as accounts, contacts, deals, activity metadata, meeting titles, times, and participants. When workspace CRM writeback is enabled, HubSpot and Salesforce writes are create-only and seller-triggered: Cernos can create tasks and notes attached to existing CRM records — Salesforce Tasks and Notes linked to Contact, Opportunity, or Account records, and their HubSpot equivalents — each carrying a visible Cernos marker so the artifact is identifiable in your CRM. Cernos does not update, overwrite, or delete customer-owned CRM records, does not change pipeline or stage fields, and writes nothing to a CRM without a seller action. Writeback can be switched off per workspace without disconnecting read sync.

Cernos does not use Zoom recording or transcription APIs and does not retain Zoom recording content, chat, or meeting audio or video. Transcript or note text that you paste into Meeting Coach or the Zoom panel is different: it is saved in your workspace as a notes artifact until you delete it.

Browser extension and desktop application. The Gmail extension reads the currently open Gmail thread when you use its pane. Cernos Desktop displays Cernos prep locally. Its meeting-detection signal is local-only: it does not access, record, transcribe, or transmit audio or video, and it does not send the local in-use signal to Cernos servers.

How long connected-service information is kept, and how to have it removed, is described in Retention and Deletion below.

How We Use Information

  • Provide, authenticate, secure, support, and improve the Service.
  • Connect authorized services and create the workspace context you request.
  • Generate seller-facing summaries, preparation, recommendations, and other requested outputs.
  • Process subscriptions, prevent abuse, enforce our terms, and meet legal obligations.
  • Communicate about your account, support requests, service changes, and security matters.

We do not sell personal information or use customer content to train Cernos general-purpose models. We do not use Google Workspace data for advertising or generalized AI or machine-learning training.

AI Features

When you ask Cernos to generate or synthesize content, the Service may send the relevant prompt, workspace context, and selected evidence to OpenAI or Anthropic to produce the requested output. The amount of information depends on the feature and the information available in your workspace. Do not submit information you are not authorized to provide. We use these providers to deliver the requested feature, not to build a general-purpose Cernos model from your customer content.

How We Share Information

We share information only as needed to run the Service, including with:

  • Clerk for authentication; Stripe for billing; Supabase for the application database; Vercel for hosting and runtime operations; and SendGrid for account, trial, and support email.
  • Google, Microsoft, HubSpot, Salesforce, and Zoom when you authorize a relevant integration.
  • HubSpot as our own customer-relationship system. Independently of any integration you connect, we record business-contact details such as your name, email address, company, workspace name, billing email, and trial or subscription stage so we can manage our own sales and support relationship with you.
  • OpenAI and Anthropic when you use an AI feature, as described above.
  • Service providers acting on our instructions, professional advisers, or authorities where required by law.
  • A successor in a merger, financing, acquisition, or sale, subject to applicable law.

We do not share personal information with data brokers or for cross-context behavioral advertising.

Cookies and Similar Technologies

Cernos uses essential cookies and similar local storage needed for sign-in, sessions, security, preferences, and service operation. We do not currently use third-party behavioral advertising cookies or third-party analytics platforms to track end-user behavior across unrelated sites.

Retention and Deletion

We retain account, workspace, and connected-service data for the life of the relevant workspace unless it is deleted sooner or we must retain it for security, tax, accounting, dispute, or legal reasons. Disconnecting an integration stops future access through that connection but does not, by itself, remove data already imported into a workspace. You can request deletion of a workspace, integration data, or personal information at privacy@cernossi.com.

We may retain limited, access-restricted backup copies and security logs for a reasonable period before they expire in the ordinary backup cycle. We will respond to verified deletion requests in accordance with applicable law and our legal-retention obligations.

Your Privacy Choices and Rights

Depending on your location and relationship to Cernos, you may have rights to request access, correction, deletion, restriction, objection, or portability. You may also revoke an integration at its provider. To make a request, email privacy@cernossi.com. We may need to verify your request and will explain if an organization that controls the workspace must handle it instead.

Security and International Transfers

Cernos uses safeguards designed to protect information, including TLS in transit, encrypted storage of OAuth credentials, access controls, and restricted production access. No method of transmission or storage is completely secure. Cernos and its providers may process information in the United States and other countries. Where required, we use appropriate transfer mechanisms.

Children and Policy Changes

Cernos is a business service and is not directed to children under 16. We may update this policy; if a change is material, we will update this page and provide additional notice where required.

Contact

Privacy requests and data-protection questions: privacy@cernossi.com
Security and compliance: security@cernossi.com
General support: support@cernossi.com

Written notice may be sent to:
Complex Sales Intelligence LLC
1013 Centre Road, Suite 403S
Wilmington, DE 19805
United States